CVE Feed

    Dashboard / CVE

    5.3
    Medium

    CVE-2016-8725

    Last Modified: 20 Apr 2025

    An exploitable information disclosure vulnerability exists in the Web Application functionality of the Moxa AWK-3131A wireless access point running firmware 1.1. Retrieving a specific URL without authentication can reveal sensitive information to an attacker.

    Published: 13 Apr 2017
    8.1
    High

    CVE-2016-8712

    Last Modified: 20 Apr 2025

    An exploitable nonce reuse vulnerability exists in the Web Application functionality of Moxa AWK-3131A Wireless AP running firmware 1.1. The device uses one nonce for all session authentication requests and only changes the nonce if the web application has been idle for 300 seconds.

    Published: 13 Apr 2017
    4.3
    Medium

    CVE-2016-8720

    Last Modified: 20 Apr 2025

    An exploitable HTTP Header Injection vulnerability exists in the Web Application functionality of the Moxa AWK-3131A Wireless Access Point running firmware 1.1. A specially crafted HTTP request can inject a payload in the bkpath parameter which will be copied in to Location header of the HTTP response.

    Published: 13 Apr 2017
    5.3
    Medium

    CVE-2016-8722

    Last Modified: 20 Apr 2025

    An exploitable Information Disclosure vulnerability exists in the Web Application functionality of Moxa AWK-3131A Series Industrial IEEE 802.11a/b/g/n wireless AP/bridge/client. Retrieving a specific URL without authentication can reveal sensitive information to an attacker.

    Published: 13 Apr 2017
    7.5
    High

    CVE-2016-8723

    Last Modified: 20 Apr 2025

    An exploitable null pointer dereference exists in the Web Application functionality of Moxa AWK-3131A Wireless Access Point running firmware 1.1. Any HTTP GET request not preceded by an '/' will cause a segmentation fault in the web server. An attacker can send any of a multitude of potentially unexpected HTTP get requests to trigger this vulnerability.

    Published: 13 Apr 2017
    7.5
    High

    CVE-2016-8726

    Last Modified: 20 Apr 2025

    An exploitable null pointer dereference vulnerability exists in the Web Application /forms/web_runScript iw_filename functionality of Moxa AWK-3131A Wireless Access Point running firmware 1.1. An HTTP POST request with a blank line in the header will cause a segmentation fault in the web server.

    Published: 13 Apr 2017
    7.5
    High

    CVE-2016-8727

    Last Modified: 20 Apr 2025

    An exploitable information disclosure vulnerability exists in the Web Application functionality of Moxa AWK-3131A Wireless Access Point. Retrieving a series of URLs without authentication can reveal sensitive configuration and system information to an attacker.

    Published: 13 Apr 2017
    6.5
    Medium

    CVE-2013-6662

    Last Modified: 23 Feb 2026

    Google Chrome caches TLS sessions before certificate validation occurs.

    Published: 13 Apr 2017
    7.5
    High

    CVE-2013-6648

    Last Modified: 20 Apr 2025

    SkRegion::setPath in Skia allows remote attackers to cause a denial of service (crash).

    Published: 13 Apr 2017
    9.1
    Critical

    CVE-2015-2947

    Last Modified: 20 Apr 2025

    KanColleViewer versions 3.8.1 and earlier operates as an open proxy which allows remote attackers to trigger outbound network traffic.

    Published: 13 Apr 2017
    9.8
    Critical

    CVE-2012-1301

    Last Modified: 20 Apr 2025

    The FeedProxy.aspx script in Umbraco 4.7.0 allows remote attackers to proxy requests on their behalf via the "url" parameter.

    Published: 13 Apr 2017
    5.4
    Medium

    CVE-2014-3887

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in I-O DATA DEVICE RockDisk with firmware before 1.05e1-2.0.5 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. NOTE: This vulnerability exists because of an incomplete fix for CVE-2013-4713.

    Published: 13 Apr 2017
    6.1
    Medium

    CVE-2017-7725

    Last Modified: 20 Apr 2025

    concrete5 8.1.0 places incorrect trust in the HTTP Host header during caching, if the administrator did not define a "canonical" URL on installation of concrete5 using the "Advanced Options" settings. Remote attackers can make a GET request with any domain name in the Host header; this is stored and allows for arbitrary domains to be set for certain links displayed to subsequent visitors, potentially an XSS vector.

    Published: 13 Apr 2017
    9.8
    Critical

    CVE-2016-1155

    Last Modified: 20 Apr 2025

    HTTP header injection vulnerability in the URLConnection class in Android OS 2.2 through 6.0 allows remote attackers to execute arbitrary scripts or set arbitrary values in cookies.

    Published: 13 Apr 2017
    9.8
    Critical

    CVE-2016-4898

    Last Modified: 20 Apr 2025

    The datamover module in the Linux version of NovaBACKUP DataCenter before 09.06.03.0353 is vulnerable to remote command execution via unspecified attack vectors.

    Published: 13 Apr 2017
    9.8
    Critical

    CVE-2016-4899

    Last Modified: 20 Apr 2025

    The datamover module in the Linux version of NovaBACKUP DataCenter before 09.06.03.0353 is vulnerable to remote command execution via unspecified attack vectors.

    Published: 13 Apr 2017
    8.8
    High

    CVE-2016-7834

    Last Modified: 20 Apr 2025

    SONY SNC-CH115, SNC-CH120, SNC-CH160, SNC-CH220, SNC-CH260, SNC-DH120, SNC-DH120T, SNC-DH160, SNC-DH220, SNC-DH220T, SNC-DH260, SNC-EB520, SNC-EM520, SNC-EM521, SNC-ZB550, SNC-ZM550, SNC-ZM551, SNC-EP550, SNC-EP580, SNC-ER550, SNC-ER550C, SNC-ER580, SNC-ER585, SNC-ER585H, SNC-ZP550, SNC-ZR550, SNC-EP520, SNC-EP521, SNC-ER520, SNC-ER521, SNC-ER521C network cameras with firmware before Ver.1.86.00 and SONY SNC-CX600, SNC-CX600W, SNC-EB600, SNC-EB600B, SNC-EB602R, SNC-EB630, SNC-EB630B, SNC-EB632R, SNC-EM600, SNC-EM601, SNC-EM602R, SNC-EM602RC, SNC-EM630, SNC-EM631, SNC-EM632R, SNC-EM632RC, SNC-VB600, SNC-VB600B, SNC-VB600B5, SNC-VB630, SNC-VB6305, SNC-VB6307, SNC-VB632D, SNC-VB635, SNC-VM600, SNC-VM600B, SNC-VM600B5, SNC-VM601, SNC-VM601B, SNC-VM602R, SNC-VM630, SNC-VM6305, SNC-VM6307, SNC-VM631, SNC-VM632R, SNC-WR600, SNC-WR602, SNC-WR602C, SNC-WR630, SNC-WR632, SNC-WR632C, SNC-XM631, SNC-XM632, SNC-XM636, SNC-XM637, SNC-VB600L, SNC-VM600L, SNC-XM631L, SNC-WR602CL network cameras with firmware before Ver.2.7.2 are prone to sensitive information disclosure. This may allow an attacker on the same local network segment to login to the device with administrative privileges and perform operations on the device.

    Published: 13 Apr 2017
    5.5
    Medium

    CVE-2016-2036

    Last Modified: 20 Apr 2025

    The getURL function in drivers/secfilter/urlparser.c in secfilter in the Samsung kernel for Android on SM-N9005 build N9005XXUGBOB6 (Note 3) and SM-G920F build G920FXXU2COH2 (Galaxy S6) devices allows attackers to trigger a NULL pointer dereference via a "GET HTTP/1.1" request, aka SVE-2016-5036.

    Published: 13 Apr 2017
    3.3
    Low

    CVE-2016-2567

    Last Modified: 20 Apr 2025

    secfilter in the Samsung kernel for Android on SM-N9005 build N9005XXUGBOB6 (Note 3) and SM-G920F build G920FXXU2COH2 (Galaxy S6) devices allows attackers to bypass URL filtering by inserting an "exceptional URL" in the query string, as demonstrated by the http://should-have-been-filtered.example.com/?http://google.com URL.

    Published: 13 Apr 2017
    6.4
    Medium

    CVE-2015-8780

    Last Modified: 20 Apr 2025

    Samsung wssyncmlnps before 2015-10-31 allows directory traversal in a Kies restore, aka ZipFury.

    Published: 13 Apr 2017
    3.3
    Low

    CVE-2016-2565

    Last Modified: 20 Apr 2025

    Samsung SecEmailSync on SM-G920F build G920FXXU2COH2 (Galaxy S6) devices allows attackers to read sent e-mail messages, aka SVE-2015-5081.

    Published: 13 Apr 2017
    9.8
    Critical

    CVE-2016-2566

    Last Modified: 20 Apr 2025

    Samsung SecEmailSync on SM-G920F build G920FXXU2COH2 (Galaxy S6) devices has SQL injection, aka SVE-2015-5081.

    Published: 13 Apr 2017
    4.6
    Medium

    CVE-2016-4032

    Last Modified: 20 Apr 2025

    Samsung SM-G920F build G920FXXU2COH2 (Galaxy S6), SM-N9005 build N9005XXUGBOK6 (Galaxy Note 3), GT-I9192 build I9192XXUBNB1 (Galaxy S4 mini), GT-I9195 build I9195XXUCOL1 (Galaxy S4 mini LTE), and GT-I9505 build I9505XXUHOJ2 (Galaxy S4) devices do not block AT+USBDEBUG and AT+WIFIVALUE, which allows attackers to modify Android settings by leveraging AT access, aka SVE-2016-5301.

    Published: 13 Apr 2017
    6.8
    Medium

    CVE-2016-4030

    Last Modified: 20 Apr 2025

    Samsung SM-G920F build G920FXXU2COH2 (Galaxy S6), SM-N9005 build N9005XXUGBOK6 (Galaxy Note 3), GT-I9192 build I9192XXUBNB1 (Galaxy S4 mini), GT-I9195 build I9195XXUCOL1 (Galaxy S4 mini LTE), and GT-I9505 build I9505XXUHOJ2 (Galaxy S4) devices have unintended availability of the modem in USB configuration number 2 within the secure lockscreen state, allowing an attacker to make phone calls, send text messages, or issue commands, aka SVE-2016-5301.

    Published: 13 Apr 2017
    6.8
    Medium

    CVE-2016-4031

    Last Modified: 20 Apr 2025

    Samsung SM-G920F build G920FXXU2COH2 (Galaxy S6), SM-N9005 build N9005XXUGBOK6 (Galaxy Note 3), GT-I9192 build I9192XXUBNB1 (Galaxy S4 mini), GT-I9195 build I9195XXUCOL1 (Galaxy S4 mini LTE), and GT-I9505 build I9505XXUHOJ2 (Galaxy S4) devices allow attackers to send AT commands by plugging the device into a Linux host, aka SVE-2016-5301.

    Published: 13 Apr 2017
    5.5
    Medium

    CVE-2017-7854

    Last Modified: 20 Apr 2025

    The consume_init_expr function in wasm.c in radare2 1.3.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted Web Assembly file.

    Published: 13 Apr 2017
    7.8
    High

    CVE-2010-1821

    Last Modified: 20 Apr 2025

    Apple Mac OS X 10.6 through 10.6.3 and Mac OS X Server 10.6 through 10.6.3 allows local users to obtain system privileges.

    Published: 13 Apr 2017
    7.8
    High

    CVE-2010-1816

    Last Modified: 20 Apr 2025

    Buffer overflow in ImageIO in Apple Mac OS X 10.6 through 10.6.3 and Mac OS X Server 10.6 through 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (crash) via a crafted image.

    Published: 13 Apr 2017
    9.8
    Critical

    CVE-2016-10324

    Last Modified: 20 Apr 2025

    In libosip2 in GNU oSIP 4.1.0, a malformed SIP message can lead to a heap buffer overflow in the osip_clrncpy() function defined in osipparser2/osip_port.c.

    Published: 13 Apr 2017
    7.5
    High

    CVE-2016-10325

    Last Modified: 20 Apr 2025

    In libosip2 in GNU oSIP 4.1.0, a malformed SIP message can lead to a heap buffer overflow in the _osip_message_to_str() function defined in osipparser2/osip_message_to_str.c, resulting in a remote DoS.

    Published: 13 Apr 2017
    9.8
    Critical

    CVE-2014-7920

    Last Modified: 20 Apr 2025

    mediaserver in Android 2.2 through 5.x before 5.1 allows attackers to gain privileges. NOTE: This is a different vulnerability than CVE-2014-7921.

    Published: 13 Apr 2017
    9.8
    Critical

    CVE-2014-7921

    Last Modified: 20 Apr 2025

    mediaserver in Android 4.0.3 through 5.x before 5.1 allows attackers to gain privileges. NOTE: This is a different vulnerability than CVE-2014-7920.

    Published: 13 Apr 2017
    7.5
    High

    CVE-2016-10326

    Last Modified: 20 Apr 2025

    In libosip2 in GNU oSIP 4.1.0, a malformed SIP message can lead to a heap buffer overflow in the osip_body_to_str() function defined in osipparser2/osip_body.c, resulting in a remote DoS.

    Published: 13 Apr 2017
    7.5
    High

    CVE-2017-7853

    Last Modified: 20 Apr 2025

    In libosip2 in GNU oSIP 4.1.0 and 5.0.0, a malformed SIP message can lead to a heap buffer overflow in the msg_osip_body_parse() function defined in osipparser2/osip_message_parse.c, resulting in a remote DoS.

    Published: 13 Apr 2017
    6.1
    Medium

    CVE-2016-4068

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.0.9 and 1.1.x before 1.1.5 allows remote attackers to inject arbitrary web script or HTML via a crafted SVG, a different vulnerability than CVE-2015-8864.

    Published: 13 Apr 2017
    6.1
    Medium

    CVE-2015-7565

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in Ember.js 1.8.x through 1.10.x, 1.11.x before 1.11.4, 1.12.x before 1.12.2, 1.13.x before 1.13.12, 2.0.x before 2.0.3, 2.1.x before 2.1.2, and 2.2.x before 2.2.1 allows remote attackers to inject arbitrary web script or HTML.

    Published: 13 Apr 2017
    5.5
    Medium

    CVE-2015-7740

    Last Modified: 20 Apr 2025

    Huawei P7 before P7-L00C17B851, P7-L05C00B851, and P7-L09C92B851 and P8 ALE-UL00 before ALE-UL00B211 allows local users to cause a denial of service (OS crash) via vectors involving an application that passes crafted input to the GPU driver.

    Published: 13 Apr 2017
    5.5
    Medium

    CVE-2015-8223

    Last Modified: 20 Apr 2025

    Huawei P7 before P7-L00C17B851, P7-L05C00B851, and P7-L09C92B85, and P8 ALE-UL00 before ALE-UL00B211 allows local users to cause a denial of service (OS crash) by leveraging camera permissions and via crafted input to the camera driver.

    Published: 13 Apr 2017
    6.1
    Medium

    CVE-2016-1915

    Last Modified: 20 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in BlackBerry Enterprise Server 12 (BES12) Self-Service before 12.4 allow remote attackers to inject arbitrary web script or HTML via the locale parameter to (1) mydevice/index.jsp or (2) mydevice/loggedOut.jsp.

    Published: 13 Apr 2017
    7.5
    High

    CVE-2012-6697

    Last Modified: 20 Apr 2025

    InspIRCd before 2.0.7 allows remote attackers to cause a denial of service (infinite loop).

    Published: 13 Apr 2017
    6.1
    Medium

    CVE-2014-2710

    Last Modified: 20 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Oliver (formerly Webshare) 1.3.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the (1) login page (index.php) or (2) login form (loginform-inc.php).

    Published: 13 Apr 2017
    9.8
    Critical

    CVE-2016-6143

    Last Modified: 20 Apr 2025

    SAP HANA DB 1.00.73.00.389160 allows remote attackers to execute arbitrary code via vectors involving the audit logs, aka SAP Security Note 2170806.

    Published: 13 Apr 2017
    9.8
    Critical

    CVE-2015-6674

    Last Modified: 20 Apr 2025

    Buffer underflow vulnerability in the Debian inspircd package before 2.0.5-1+deb7u1 for wheezy and before 2.0.16-1 for jessie and sid. NOTE: This issue exists as an additional issue from an incomplete fix of CVE-2012-1836.

    Published: 13 Apr 2017
    7.8
    High

    CVE-2016-10120

    Last Modified: 20 Apr 2025

    Firejail uses 0777 permissions when mounting (1) /dev, (2) /dev/shm, (3) /var/tmp, or (4) /var/lock, which allows local users to gain privileges.

    Published: 13 Apr 2017
    7.5
    High

    CVE-2015-8270

    Last Modified: 20 Apr 2025

    The AMF3ReadString function in amf.c in RTMPDump 2.4 allows remote RTMP Media servers to cause a denial of service (invalid pointer dereference and process crash).

    Published: 13 Apr 2017
    9.8
    Critical

    CVE-2015-8271

    Last Modified: 20 Apr 2025

    The AMF3CD_AddProp function in amf.c in RTMPDump 2.4 allows remote RTMP Media servers to execute arbitrary code.

    Published: 13 Apr 2017
    6.5
    Medium

    CVE-2015-8272

    Last Modified: 20 Apr 2025

    RTMPDump 2.4 allows remote attackers to trigger a denial of service (NULL pointer dereference and process crash).

    Published: 13 Apr 2017
    9.8
    Critical

    CVE-2015-8282

    Last Modified: 20 Apr 2025

    SeaWell Networks Spectrum SDC 02.05.00 has a default password of "admin" for the "admin" account.

    Published: 13 Apr 2017
    6.5
    Medium

    CVE-2015-8283

    Last Modified: 20 Apr 2025

    Directory traversal vulnerability in configure_manage.php in SeaWell Networks Spectrum SDC 02.05.00.

    Published: 13 Apr 2017
    8.8
    High

    CVE-2015-8284

    Last Modified: 20 Apr 2025

    SeaWell Networks Spectrum SDC 02.05.00 allows remote viewer users to perform administrative functions.

    Published: 13 Apr 2017